A Steam data breach has hit customers who bought Valve hardware in Europe over the past few months. Valve confirmed that hackers breached CEVA Logistics, the company that ships Steam Deck, Steam Controller, and Steam Machine orders across Europe, between July 29 and August 1, 2026. Valve learned of the incident on August 7 and started emailing affected customers on August 10. The breach exposed names, addresses, phone numbers, and email addresses linked to hardware orders. Account passwords, Steam Guard codes, and payment details were not affected.
Here is what happened and what affected users should do next.
What Caused the Steam Data Breach
Valve said CEVA Logistics suffered a cyberattack between July 29 and August 1, 2026. CEVA handles shipping for Steam hardware orders across Europe, including the Steam Deck, Steam Controller, and Steam Machine. Valve added that it only learned of the compromise on August 7, four days after the attack window closed.
CEVA Logistics is a subsidiary of the CMA CGM Group, the world’s third-largest shipping company. The firm runs more than 1,000 warehouses and handled 15 million shipments last year, generating $18.3 billion in revenue in 2025. CEVA also notified several other European retailers about the same cyberattack on August 1.
According to Valve, CEVA keeps delivery information for up to 90 days after an order ships. This means the Steam data breach only affects customers who bought Valve hardware within roughly the past three months.
What Information Was Exposed in the Steam Data Breach
Valve listed the specific details CEVA held that attackers likely accessed:
- Full name
- Street address, postal code, and city
- Country
- Phone number
- Email address linked to the Steam account
- Type and price of the ordered hardware
Valve confirmed that no Steam account information was affected in this Valve data breach. CEVA never had access to payment details, Steam passwords, Steam Guard codes, or other account data. Attackers cannot use the leaked information to log into anyone’s Steam account.
Valve Warns of Phishing Attempts After the CEVA Logistics Cyberattack
Valve told affected Steam hardware customers to expect fake messages by email, SMS, or phone that reference their order. Scammers may already have real details, like a customer’s address, which they can use to make the messages look genuine.
These messages could ask users to confirm a delivery, pay a small customs or redelivery fee, or log in to “verify” an order. Valve said customers should treat every such message as fraudulent. Steam Support never contacts users through Steam Chat, Discord, or email, and only operates through help.steampowered.com.
Valve also confirmed that Steam hardware customers do not need to change their password or update any account settings, since login credentials remain unaffected by this Steam phishing scam risk.

